Ryde Data Breach: 4.5 Million Leaked in Norway, Sweden, Finland, Germany
Photo: Estormiz / Wikimedia Commons / CC0 1.0
The Ryde data breach reached every single customer the scooter rental company has. Roughly 4.5 million accounts across Norway, Sweden, Finland and Germany were copied out of its systems during the night into Sunday 2 August 2026, with about 1.6 million of them in Norway alone. Ryde is not disputing the scale: in its own words, this applies to everyone with an account.
What Ryde Says Happened
According to the company's incident statement, unauthorised parties reached its systems overnight on 1 to 2 August and copied customer data before the access was closed. Ryde says it has since shut the entry points it identified, rebuilt the affected systems, and replaced passwords and cryptographic keys. It reported the breach to Datatilsynet, the Norwegian data protection authority, and to the police.
Chief executive Tobias Balchen told NRK that unauthorised persons gained access and copied out certain customer information, and that it applies to everyone with an account. He also said the company has no indication of who is behind it and has received no payment demand and no threats. That last point is worth holding onto, because it is not reassuring in the way it sounds: a set of stolen personal records with no ransom attached is a set that is more likely to be sold or simply published.
What Was Taken, and What Was Not
The stolen fields are phone numbers, email addresses, dates of birth, the first six and last four digits of payment cards, payment history covering rides, purchases and fees, and the location where the account was created. For some customers an unverified name and address were included as well.
Two things were not taken, and both matter. Full card numbers are held by Ryde's payment provider rather than by Ryde, so there is no need to block a card. And travel history is not part of it: the company states there is no indication that data about where you have ridden was affected. If you saw a summary claiming your trip routes leaked, that summary was wrong. What leaked is the money trail, not the map.
Why the First Six Digits Matter
The first six digits of a payment card are the issuer identification number. They are not secret, but they identify the bank that issued the card. Combined with the last four digits, which is exactly what a bank prints on a statement, they let someone write to you saying which bank you are with and quoting the visible ending of your own card.
Add a date of birth, a phone number, and a payment history showing what you actually spent and when, and the message stops looking like spam. This is why a breach of a scooter app becomes a banking problem: the attacker does not need your bank's systems, only enough detail to sound like your bank.
The BankID and Bank Credential Problem
Ryde's own advice is the right one and deserves repeating in full: never give your passwords, banking codes or BankID credentials to anyone who contacts you, no matter how credible they seem. In Norway and Sweden, BankID is not just a login, it is a legally binding signature. A person who talks you through a BankID confirmation can move money and enter agreements in your name. In Finland the same role is played by online banking credentials in the Finnish Trust Network, and in Germany by the TAN confirmation in your banking app.
The leaked phone numbers put the phone-linked payment apps in scope too. Vipps in Norway, Swish in Sweden and MobilePay in Finland all work off a mobile number, which is the one identifier this breach handed over for every single customer. A payment request that arrives in one of those apps carries no email header to inspect and no link to hover over, and it lands in a place people are used to approving quickly.
The pattern to expect is a phone call or message that opens with details only your bank should know, creates urgency about a suspicious payment, and ends by asking you to confirm something. No bank, no police force and no company ever needs you to read out a code or approve an identity confirmation you did not start yourself. If a call goes that way, the correct response is to hang up and call the number printed on your own card.
What to Do in Norway, Sweden, Finland and Germany
- Do not block your card: full numbers were not exposed. Blocking creates hassle without reducing the actual risk, which is social engineering.
- Treat any contact about this breach as hostile until proven otherwise: attackers read the same news you do, and the first wave of phishing after a public breach is usually branded with the breached company's name.
- Check your statements for small amounts, not large ones: testing charges are deliberately trivial, and payment history from this leak tells an attacker what a normal amount looks like for you.
- Change the password if you reused it: Ryde says it replaced passwords on its side, but if the same one opens your email, that is the account worth fixing today.
- Know where to complain: Ryde is Norwegian, so Datatilsynet acts as the lead supervisory authority for the whole case. Residents of Sweden can still file with IMY, Finnish residents with the Office of the Data Protection Ombudsman, and German residents with their state authority; each forwards to the lead authority under the one-stop-shop rules.
- Watch the phone, not just the inbox: phone numbers leaked alongside the rest, which puts SMS, voice calls and payment requests in Vipps, Swish or MobilePay in scope, and none of those pass through an email filter.
Why This Matters Beyond Scooter Riders
A scooter app is a small thing to sign up for and it ended up holding a birth date, a phone number, a bank identifier and a record of spending. That is the actual cost of the "just log in with your phone number" convenience layer that sits under most city mobility services, and it is the same arithmetic behind the credentials that ended up in the open database holding 24 billion leaked passwords and behind the breach of a UK police legal database. On the honest limits: a VPN would not have prevented any of this, because the data was taken from the company's servers, not from your connection. What network privacy tools do help with is the next stage, since DNS filtering and blocklists stop a good share of phishing pages from loading at all, and using fewer real details when a service does not need them shrinks what any future breach can carry.